I x< ! wvdFHX 


Availability: _Low_Moderate.High.JUisdefmed 

Not applicable - this system is only paper-based. 

19. Does the sy stem conduct data mining as defined in Section 804 of the 

Implementing Recommendations of the 9/11 Commission Act of 2007. P,L. 1:19- 
53 (codified at 42 USC 2909ee-3)? 

X NO 

__YES If yes, please describe the data mining function: 

11, is this a national security system (as determined by the Sec!)}? 

,X ’NO _YES 

111 Status of System/ Project: 

This is a new system/ project in development. 

l.L EXISTING SYSTEMS / PROJECTi'S 

1. When was the system/project developed? 

The system was developed in Oct 2005 

2. Has the system/project undergone any significant changes since April 17. 2003? 

___ A NO | If no. proceed to next question (II..3},j 

X YES If yes Judicale which of the following changes were involved (mark all 
changes that apply, and provide brief explanation for each marked change); 

_X_ A conversion from paper-based records to an electronic system. 

_ A change from Information is: a format that is anonymous or non- 

ide.ntih.able to a format that is identifiable to particular individuals. 

A new use of an IT systern/projccL including application of a new 
technology, that changes how information in identifiable form is managed. 
(For example, a change that would create a more open environment tend or 
u\ critic tor exposure of data that prev antsls did not exist) 

IJNCXASSIflEfl 
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V ^0 ^ ‘ ' in \\ 's ! O’ \ ' < ' NsS 

A new method of authenticating the use of and access to 
s " O' \o 1 fo K o o ' o\ "O' 'om t 'o ' *’ .. 

A systematic incorporation of databases of information m 
identifiable form purchased or obtained front commercial or public sources. 

A new interagency use or shared agency function that results in 
new oxw n" ^ vkmccN .g nxfourat -m -o akmufofoo fonn 

A change that results in a new use or disclosure of information in 
identifiable, form. 

\ \,' ‘ ' O'- W > >\ " > ' \ O ‘ < < ' V > 

form being added into the systcm/proiect. 

\ 'O ' v O W V ' 0 S X u'.vvO O' Ovfo 'W ' \ ' 'Ov 
over the years to stay current with new .research in the fitness industry. For 
example, core strength was once tested through sit-ups. and then it was 
abdominal crunches. It is now is tested, with the plank hold. The basic 
.\ . o<"s ' "< t r oof. ucJ ,o '.a too - ”oo 

Changes do not involve a change in the type of records maintained, 
the individuals on whom records arc maintained, or the use or 
mwerimafser m mform.rnoK horn 'ho .\w'Vm p"-de.n 

Other l Provide brief explanation): 

Does a PI A for this systcm/project already exist? 

.X.'NO .YES 


a. Provide date/tdle of the FI A; 

u\ . v -o v*. o o o v't 'oo yo"o o"\ s "y' \ . s P \ * 

YES 


! J Y C; I, ,4 bA f I'! E .0 
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(OGC/PCLU (Rev. 01/05/09) 


FBI PRIVACY THRESHOLD ANALYSIS (PTA) 

(Equivalent to the DOJ Initial Privacy Assessment (IPA)) 


NAME OF SYSTEM / PROJECT: Commercial Payments Unit Invoice Management System (CPUIMS) 


Derived From: 

SYSTEM/PROJECT POC 

FBI OGC/PCLU POC 

Classified Bv: 

Name:| "| 

Name: 



Reason: 

Program Office: Information Technology 

Phone 



Declassify On: 

Operations Division (ITOD) 

Division: Financial Systems Unit 

Room Number: 7338 


Phone! 1 

Room Number: 1302 




FBI DIVISION INTERMEDIATE APPROVALS [complete as necessar 

/] 


Program Manager (or other appropriate 
executive as Division determines) 

Division Privacy Officer 

Program Division: 

Signature: | | 

Signature: 

1 

Financial Systems Unit 

Date signed: hrW^l 

Date signet 

: u b/nm 


Name:| | 

Name: | 



Title: IT Specialist 

Title: iToh 

pfwaoi Officer 

FBIHQ Division: 

Signature: 

Signature: 



Date signed: 

Date signed: 


Name: 

Name: 



Title: 

Title: 



Additional division(s) approvals may be added as warranted: 


After all division approvals, forward signed hard copy plus electronic copy to FBI OGC/PCLU (JEH 7338). 

(The FBI Privacy and Civil Liberties Officer's determinations, conditions, and/or final approval will be recorded on the 
following page.) 


Upon final FBI approval, FBI OGC/PCLU will distribute as follows: 

1 - Signed original to file 190-HQ-C1321794 (fwd to JEH 1B204 via PA-520) 

Copies (recipients please print/reproduce as needed for Program/Division file(s)): 

1 - DOJ Office of Privacy and Civil Liberties (via e-mail to privacy@usdoj.gov) 

(if classified, via hand delivery to 1331 Penn. Ave. NW, Suite 940, 20530) 

2 - FBI OCIO / OIPP (JEH 9376, attn:| ~| _ 

1 - FBI SecD/AU (ele ctronic copy: via e-m ail to UC 

1 - RMD/RMAU (attnj | - 

2 - Program Division POC /Privacy Olficer 
2 - FBIHQ Division POC /Privacy Officer 


1 - OGCYPCLU intranet 
1 - PCLU UC 
1 - PCLU Library 
1 - PCLU Tickler b6 
b7C 
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FBI PTA: CPUIMS 


[UNCLASSIFIED/FOR OFFICIAL USE ONLY] 


FINAL FBI APPROVAL / DETERMINATIONS / CONDITIONS: [This section will be completed by the FBI 
PCLU/PCLO following PTA submission. The PTA drafter should skip to the next page and continue.] _ 

_PIA is required by the E-Govemment Act. 

_PIA is to be completed as a matter of FBI/DOJ discretion. 

Is PIA to be published on FBI.GOV (after any RMD FOIA redactions)? _Yes. _No (indicate reason): 


X PIA is not required for the following reason(s): 

_System does not collect, maintain, or disseminate PII. 

_X_ System is grandfathered (in existence before 4/17/2003; no later changes posing significant privacy 

risks). 

_Information in the system relates to internal government operations. 

_System has been previously assessed under an evaluation similar to a PIA. 

_No significant privacy issues (or privacy issues are unchanged). 

_Other (describe): 


Applicable SORN(s): DOJ-OOl, Accounting Systems for the Department of Justice (DOJ). 

Notify FBI RMD/RIDS per MIOG 190.2.3? X No _Yes (see sample EC on PCLU intranet website). 

SORN/SORN revision(s) required? _X_No _Yes (indicate revisions needed): 


Prepare/revise/add Privacy Act (e)(3) statements for related forms? X No _Yes (indicate forms affected): 


RECORDS. The program should consult with RMD to identify/resolve any Federal records/electronic records issues. 
The system may contain Federal records whether or not it contains Privacy Act requests and, in any event, a records 
schedule approved by the National Archives and Records Administration is necessary. RMD can provide advice on 
this as well as on compliance with requirements for Electronic Recordkeeping Certification and any necessary updates. 

Other: 


David C. Larson, Deputy General Counsel Signature: 

FBI Privacy and Civil Liberties Officer Date Signed: 
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UNCLASSIFIED//FOR OFFICIAL USE ONLY 


I. INFORMATION ABOUT THE SYSTEM / PROJECT 


1. Provide a general description of the system or project that includes: name of the system/project, including 
associated acronyms; structure of the system/project, purpose; nature of the information in the system and 
how it will be used; who will have access to the information in the system and the manner of transmission to al 
users. (This kind of information may be available in the System Security Plan, if available, or from a Concept of 
Operations document, and can be cut and pasted here.): 


The Finance Division’s Commercial Payments Unit Invoice Management System (CPUIMS) is a general support 
system in operation since May 17, 2000, supporting the FBI mission by providing an Electronic Document 
Management System (EDMS) that automates and manages the processing of commercial invoices within the 
Commercial Payments Unit (CPU). CPUIMS provides Commercial Payments and Confidential Services Unit 
(CPCSU) supervisors with an effective tool to manage the invoice payment workflow in real-time. The EDMS 
workflow employs standard routes and business practices that invoices follow throughout the payment process by 
utilizing document scanning and imaging software for viewing, organizing, filing, and storing commercial invoices. 


CPUIMS [ 


with customization per CPU’s requirements] 


bPUIMSf 


ICo mmercial off the Shelf (COTS) product 


CPUIMSr 


I bpi 

CPUIM S 


users will be logging into the FBINET domain[ 


workstations are located in authorized FBI controlled facilities. T 


~~|lnvoices are scanned on CPCSU client workstations! 


> allow users to view the original invoice 


at any step in the process. 
The CPUIMSl 


_J defined by the CPUIMS system. 


] UPUIMS [| 


| |COTR/CO users to input, validate, and index the invoice information that 

they submit to CPCSU for processing in CPUIMS. r | b7E 


cpuims r 

(FMS). [_“ 


3 ms mainframe application [ 


""[Financial Management System 


Access to CPUIMS requ ires FBI personnel to have and maintain a user account on the FBINET domain^ 


,_, Users must authenticate into the FBINET domain in order to log into the CPUIMS b7E 

workstation. User access to CPUIMS application! I 
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UNCLASS I FIE D//FOR OFFICIAL USE ONLY 
CPUIMS 


2. Does the system/project collect, maintain, or disseminate any information about individuals in identifiable 
form, i.e., is information linked to or linkable to specific individuals (which is the definition of personally identifiable 
information (PII))? 

_NO. [If no, STOP. The PTA is now complete and after division approval(s) should be submitted to 

FBI OGC/PCLU for final FBI approval. Unless you are otherwise advised, no PIA is required.] 

X YES. [If yes, please continue.] 


3. Does the system/project pertain only to government employees, contractors, or consultants? 
_NO. _X_YES. - 


4. Is information about United States citizens or lawfully admitted permanent resident aliens retrieved from the 
system/project by name or other personal identifier? 

_NO. yes. 


5. Are Social Security Numbers (SSNs) collected, maintained or disseminated from the system/project? 
_NO. _X_ YES. If yes, check all that apply: 


_ SSNs are necessary to establish/confirm the identity of subjects, victims, witnesses 
or sources in this law enforcement or intelligence activity. 


SSNs are necessary to identify FBI personnel in this internal administrative system. 


_ X SSNs are important for other reasons. Describe: Certain vendors I | b7E 

| uses their SSN on invoices |~ | 

_The system/project provides special protection to SSNs (e.g., SSNs are encrypted, hidden from all 

users via a look-up table, or only available to certain users). Describe: 

_It is not feasible for the system/project to provide special protection to SSNs. Explain: 

6. Does the system/project collect any information directly from the person who is the subject of the information? 

X NO. [If no, proceed to question 7.] 

_YES. 


a. Does the system/project support criminal, CT, or FCI investigations or assessments? 


UNCLASSIFIED//FOR OFFICIAL USE ONLY 
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UNCLASSIFIED//FOR OFFICIAL USE ONLY 
CPUIMS 

YES. [If yes, proceed to question 7.] 


NO. 


b. Are subjects of information from whom the information is directly collected provided a written 
Privacy Act (e)(3) statement (either on the collection form or via a separate notice)? 

_NO. [The program will need to work with PCLU to develop/implement the necessary 

form(s).] 

_YES. Identify any forms, paper or electronic, used to request such 

information from the information subject: 


7. Has the system undergone Certification & Accreditation (C&A) by the FBI Security Division (SecD)? 

_ NO. If no, indicate reason; if C&A is pending, provide anticipated completion date: 

X YES. If yes, provide date of last C&A certiflcation/re-certification: JANUARY 24, 2008 


Don't Know. 


8. Is this system/project the subject of an OMB-300 budget submission? 

X NO. _Don't know. __ YES. If yes, please provide the date and name 

or title of the OMB submission: 


9. Is this a national security system (as determined by the SecD)? 

X NO. _YES. _Don't know. 


10. Status of System/ Proj ect: 

_ This is a new system/ project in development. [If you checked this block, STOP. The PTA is now 

complete and after division approval(s) should be submitted to FBI OGC/PCLU for final FBI 
approval and determination if PIA and/or other actions are required .] 


II. EXISTING SYSTEMS / PROJECTS 

1. When was the system/project developed? May 17, 2000 

2. Has the system/project undergone any significant changes since April 17, 2003? 


UNCLASSIFIED//FOR OFFICIAL USE ONLY 
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IJNCLASSIFIED//FOR OFFICIAL USE ONLY 
CPUIMS 


X_ NO. [If no, proceed to next question (II.3).] 


YES. If yes, indicate which of the following changes were involved 

(mark all boxes that apply): 

_ A conversion from paper-based records to an electronic system. 


_ A change from information in a format that is anonymous or non-identifiable to a format that 

is identifiable to particular individuals. 

_ A new use of an IT system/project, including application of a new technology, that changes 

how information in identifiable form is managed. (For example, a change that would create a 
more open environment and/or avenue for exposure of data that previously did not exist.) 

_ A change that results in information in identifiable form being merged, centralized, or 

matched with other databases. 

_ A new method of authenticating the use of and access to information in identifiable form by 

members of the public. 

_ A systematic incorporation of databases of information in identifiable form purchased or 

obtained from commercial or public sources. 

_ A new interagency use or shared agency function that results in new uses or exchanges of 

information in identifiable form. 

_ A change that results in a new use or disclosure of information in identifiable form. 

_ A change that results in new items of information in identifiable form being added into the 

system/project. 

_ Changes do not involve a change in the type of records maintained, the individuals on whom 

records are maintained, or the use or dissemination of information from the system/project. 

_ Other. [Provide brief explanation]: 


3. Does a PIA for this system/project already exist? X_ NO. _YES. If yes: 

a. Provide date/title of the PIA: 

b. Has the system/project undergone any significant changes since the PIA? _NO. _YES. 

[The PTA is now complete and after division approval(s) should be submitted to FBI OGC/PCLU for final FBI 
approval and determination if PIA and/or other actions are required .] 


UNCLASSIFIED//FOR OFFICIAL USE ONLY 
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FBI PRIVACY THRESHOLD ANALYSIS (FI'A) 

\\MI OFMMIM f ' * . *\n E 


q\m:- ;w Mo o' - -qa 


v *s * % !«* \ x \\«r m w» yFi \ * *v.q «* > w n UMu g m e M' - i i eM n Uun 

(Pl'A).. 

Whether or ml a PIA 1$ the system. owAer/pmgmm manager Him U cornet with the FBI 

Records Muoag meet > x sk (RMD) it ec iy and resolve any tec mb smuts Ming to 1: fca&atia& k 
the system. 


x VN S ' v S N ' t X * ' V\\ 

The questions are as follows; 


r system description. 


A, Generttl System Reseriptkm 


' \ W * < N ' N S' ? *, "* k S' \ v 

f AMS receives and disseminates organmatronal message traffic Irons Other Government- Agencies 


The system receives mielbgericc Information Reports (IIRSQ 


a, If the system la solely related to internal goverwoern operations please provide a brief 
cxpiaoalon of the gnooilty and Ape of esnpktyee/coniraeicr m:torroaTk;n: 

IYe system is used lot automated internal toad eg of mesas sex received by the F.8L Tit* system 
ottly serves as a coodnn tot there toessages. and routmg is avoomeslrheb tnaomsubaily by computer bused ou 
addressing parameters in each message., No users access, tit* content of tit* transiting messages wb.it* withi-: the 
boundaries of the system. if the messages ate ehmva or wed by the t Si n o dfepe a it* to.be messages too * lek 
the FAM$ Systran. The system sloes keep a backup of messages as a contingency to emote eoruimhty of 
operations so ease of casualty or other system diarnpkoa. However, the backup data would only is* used to 

- H< >. \ u>. * < v v vO W u v. t i I rt', I'OO 

data resides on She system lor no i-sopor than ah days. 

2. Purpose for collecting the inibrntatk.es and bow it will be used: 

I \ Mb o n r o'o'"'d ovenanbe, b: etc., u, uonel mom ,m,s Lev >da -v no- v .die* to i mu 
transmitted to other government agencies and internal entities within the Lid I for the purpose of 
responding to requests or act lots items from other agencies. 


f AMS consists of Mo enclav es: Secret \ 

I | IV-1 t MLwam I - 


Hand i op bv.t'vt m |Q 


4. Meads d! oceessme the system and transmitting miitnwation i.o and from the system: 
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FBI PRIVACY THRESHOLD ANALYSIS fPTAf 
S\MI- Oi s%MI M* ^ 'j ' \j\k m> v,i 


administrative functions of the system arc 
functions consists of creeling accounts io: 
message delivery. These privilege users r 


mj _ | Ad m i tn s it ad ve b i e 

inis and sett ing up profiles for 

" |S vs tem Ad rn u i At tarots. 


Only the System Administrator and information. System Security Officers ha ve access to tire 
Is for- ensuring that only authorized persons can access tire information, PAMS | | 

|No one can access the system who rs not authorized to do so. 

6. Who outside the FBI wall have access to the information m the system and controls for ensuring 
that, only authorized persons cart access the bdormation: 

No personnel can access the system .from outside the FBI. infonnatrotr from tire system is sent, to 
other Organizations by FBI personnel The PAMS system can send organizational message traffu 


s this system encompassed within an. OMBGOO? X Yes N 

(A copy of the OMB 300 is available on the FBI Sha.repo.mt Serve 


Was the Systran dev doped prior to April f ?, 2003? 


£• of thorn chances: N/A 


srprete and should be seat te FBI OGCA Privacy and CAP Ubcnies 
tad Oa vvcKung so DOFs Privacy end Co b Llberhes Office. Unless 
a required f 
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FBI PRIVACY THRESHOLD ANALYSIS (PTA) _ (QOC/PO..U (Rev. CYOmOT; 

\ \MI Ol vh v \j,' e'WwxO ^ow l ~| 

2. Do -Do changes m solve the collection. maintenance. or disaeminahost of iniortnabon in •dentiflabie 
lot' Avm tstdh sduaid' 

YL$ (if' yes.please proceed to Question 3. > 

MO iff “no?' the PTA ft complete and then id be sent to I : BI OOCY Privacy nod Civil Liberties 
link fPCLLb for review, approval, and forwarding to DOFs Privacy and Civil Liberties Office. Unless 
>'00 lire otitervnse advised. no PIA k tec:nised.) 

3 Is toe system solely related to interns! government operations'? Yes 

.YUS If "yes.' 1 is this a Major Issformation System (as listed on OGCY FB1NLT wehsne)?; 

.Yes. (If yes?’ a lid! PI A is repaired.. FT A is complete.; 

.No. (ff Atom fbv PTA is complete and should be seat to FBI OOCY Privacy 

and Civil Liberties Unit iPCLU t tor review-, approval, and forward is tg to DOTY 
Privacy and Civil Liberties Office. Unless yon are otherwise advised, no PIA is 
required. (FBI and QOi reviewing officials reserve the right to require a PIA )} 

.NO Hi Otof go 1o section ill to determine if a Sail or short-font; IN A is required.,* 

IL For systems developed after April 17, 2003. 

1. What is the purpose of the system? (Answer in detail unless details already provided in A. 2 above): 
See Pen a above, 

(Confines to Question 2,) 

2. Dews the system collect; mturdtun or disseminate m formation it? identifiable form about mdivlbnals'? 

.NFS iff Acs," please proceed to Question 3.) 

.A NO tirmo?’ she PTA is complete and should be seal b.i FBI OGCY Privacy and Civil 

Liberties Umt(PCLU) for review, approval, and forwarding to DOTY Privacy and Civil Liberties 
Office. Unless you are otherwise advised, no PIA is required.) 

A.s discussed above, this system u merely a conduit tor transiting messages. 

Note: Although this would nonnally complete tire PTA based on absence of (ML we ate cowinomg further to 
oocnmem that even if the system were viewed as containing PIT, the system won Id also exempt from completing 
a IMA based on being solely related to internal government operations. 

3. Is the system solely related to internal government operations? 

. NFS if “yes/ 1 is this a Major Information Syslern t as listed on OGCs FBIN'LT webstte)'?. 

.Yes. NryesC a mil PIA is repaired.. FT A is complete..} 
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SENSITIVE BUT UNCLASSIFIED 

FBI Privacy Threshold Analysis (PTA) Cover Sheet (OGC/PCLU (Rev. 05/02/07) 

NAME OF SYSTEM: DEPUTATION DATABASE 



SYSTEM POC 

FBI OGC/PCLl 

POC 

Classified'" By; 

Name: 1 1 

Name: 

1 


Program Office: ITB 

Division: IT Operations 

L-l— 

Tnonel 

1 


Phone: | j 

Room Number: 8979 

Room Number: 7338 


FBI DIVISION APPROVALS A PiA (and/or PTA) should be prepared/approved by the cognizant program management in 
collaboration with IT, security, and end-user management and OGC/PCLU. (PIAs/PTAs relating to electronic forms/questionnaires implicating 

the Paperwork Reduction Act should also be coordinated with the RMD Forms Desk.) If the subject of a PTA/PIA is under the program 
cognizance of an f-'BIHQ Division, prior to forwarding to OGC the PTA/PIA must also be referred to the f-'BIHQ Division for program review and 
approval, if required by the FBIHQ Division. 



Program Division: 

FBIHQDivision:Criminaf Investigation 

Program Manager 

Signature: 

Signature: /s/ 

(or other appropriate 

Date signed: 

Date signed: 5/21/08 

executive as Division 

Name: 

Name l ~~l 

determines) 

Title: 

Title: Program Manager 

Division Privacy Officer 

Signature: 

Signature: /s/ 


Date signed: 

Date signed: 5/21/08 


Name: 

Name: l_1 


Title: 

Title: CID Division Policy Officer 


Upon Division approval, forward signed hard copy plus electronic copy to OGC/PCLU (|EH Room 7338), 


FINAL FBI APPROVAL: 


FBI Privacy and Civil Liberties Officer 

Signature: /s/ 



Date Signed: 6/21/08 



Name: 

David C. Larson 


Title: 

Deputy General Counsel 


Upon final FBI appr; 

1 - Si 


il, FBI OGC will dist ribute as follows: 

igned original to 190-HQ-C1321794 


1 - DOJ Privacy and Civil Liberties Office-Main Justice, Room 4259 

2 - FBI OCIO / OIPP 

1 - FBI SecD (electronic copy via e-mail) 

2* - Program Division POC /Privacy Officer 
2*- FBIHQ Division POC/Privacy Officer 

(*please reproduce as needed for Program/Division file(s)) 


1 - OGC\PCLU intranet website 
1 -PCLU UC 
1 - PCLU Library 
1-PCLU Tickler 
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FBI PRIVACY THRESHOLD ANALYSIS (PTA) 

NAME OF SYSTEM: DEPUTATION DATABASE 

For efficiency, a system owner or program manager can be aided in making the determination of whether a Privacy Impact Assessment 
(PIA) is required by conducting and following Privacy Threshold Analysis (PTA). 

Whether or not a PIA is required, the system owner/program manager should consult with the FBI Records Management Division (RMD) to 
identify and resolve any records issues relating to information in the system. 

A PTA contains basic questions about the nature of the system in addition to a basic system description. The questions are as follows: 

A. General System Description: Please briefly describe: 

1. Type of information in the system: 

The database contains the taskforce names for each of the FBI's field offices, the program that has oversight of the task 
force, the type of deputation requested (Title 18 or Title 21), case file number, task force officers names, social security 
numbers, and dates of deputation. 

a. If the system is solely related to internal government operations please provide a brief explanation of the quantity and type of 
employee/contractor information: 

The database is holding historic information concerning the FBI's task force officers. This 

information is used to provide the Director with the number of deputized officers and the types of deputations they are 
holding. The information is also used to remind field offices to deputize officers whose deputation are getting ready 
to expire. 

2. Purpose for collecting the information and how it will be used: 

The information is collected as a way to track all deputized taskforce officers and to provide information concerning the 
officers to the Director and the FBI's field offices. 

3. The system’s structure (including components/subsystems): 

The Deputation Database] j 

I- -1 


4. Means of accessing the system and transmitting information to and from the system: 

The application will have a link off the FBI Homepage (listed under applications). Verification for access to the 
application is done using the customer's FBINET username through Active Directory. If successful, the username is 
searched in the application's User Table to verify access to the application. The application uses the Internet Explorer to 
present the application screens to the customers. 


5. Whowithin FBI will have access to the information in the system and controls for ensuring that only authorized persons 
can access the information: 


SENSITIVE BU NCl,ASS?F>ED 
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FBI PRIVACY THRESHOLD ANALYSIS (PTA) 

NAME OF SYSTEM: DEPUTATION DATABASE 

Access will be limited to the Criminal Investigation Division Operational Support Section Administrative Unit at 
Headquarters and to employees responsible for the processing the deputation candidates in the Field Offices. 

The application has a role based security matrix for access and manipulation of the data. The application will have a 
System Administrator (ITOD) and an Owner (Criminal Investigation Division) who will have access to the User Table. 

It will be the Owner's responsibility for granting access to the database for the following roles: Reports Only, Read 
Only, Modify, and Owner. The Owner is the only one who grant access to the field offices. It will betheSystem 
Administrator's responsibility to grant access for the Admin and Owner roles. 

6. Who outside the FBI will have access to the information in the system and controls for ensuring that only authorized persons 
access the information: 

No one outside the FBI will have access to the application. 

7. Has this system been certified and accredited by the FBI Security Divisions? Yes _X_No 

8 Is this system encompassed within an OMB-300? _Yes _X_No _Don't Know 

(If yes, please attach copy of latest one.) 


Was the system developed prior to April 17, 2003? 

_X_ YES (If "yes," proceed to Question 1.) 

NO (If "no," proceed to Section II.) 

1. Has the system undergone any significant changes since April 17,2003? 

_YES If "yes," please explain the nature of those changes: 

(Continue to Question 2.) 

_X_NO (If "no," the PTA is complete and should be sent to FBI OGC's Privacy and Civil Liberties Unit (PCLU) for review, approval, 

and forwarding to DOJ's Privacy and Civil Liberties Office. Unlessyou are otherwise advised, no PIA is required.) 

2. Do the changes involve the collection, maintenance, or dissemination of information in identifiable form about individuals? 

_YES (If "yes," please proceed to Question 3.) 

_NO (If "no," the PTA is complete and should be sent to FBI OGC's Privacy and Civil Liberties Unit (PCLU) for review, approval, 

and forwarding to DOJ's Privacy and Civil Liberties Office. Unlessyou are otherwise advised, no PIA is required.) 

3. Is the system solely related to internal government operations? 
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FBI PRIVACY THRESHOLD ANALYSIS (PTA) 

NAME OF SYSTEM: DEPUTATION DATABASE 

_YES If "yes," is this a Major Information System (as listed on OGC's FBINET website)?: 

_Yes. (If "yes," afull PIA is required.. PTA is complete.) 

_No. (If "no," the PTA is complete and should be sent to FBI OGC's Privacy and Civil Liberties Unit (PCLU)for 

review, approval, and forwardingto DOJ's Privacy and Civil Liberties Office. Unless you are otherwise advised, 
no PIA is required. (FBI and DOJ reviewing officials reserve the right to require a PIA.)) 

_NO (If "no," go to section III to determine if afull or short-form PIA is required.) 


II. For systems developed after April 17, 2003. 

1. What is the purpose of the system? (Answer in detail unless details already provided in A. 2 above): 


(Continue to Question 2.) 

2. Does the system collect, maintain or disseminate information in identifiable form about individuals? 

_YES (If "yes," please proceed to Question 3.) 

_NO (If "no," the PTA is complete and should be sent to FBI OGC's Privacy and Civil Liberties Unit (PCLU)for review, approval, 

and forwarding to DOJ's Privacy and Civil Liberties Office. Unlessyou are otherwise advised, no PIA is required.) 


3. Is the system solely related to internal government operations? 

_YES If "yes," is this a Major Information System (as listed on OGC's FBINET website)?: 

_Yes. (If "yes," afull PIA is required.. PTA is complete.) 

_No. (If "no," the PTA is complete and should be sent to FBI OGC's Privacy and Civil Liberties Unit (PCLU) 

for review, approval, and forwardingto DOJ's Privacy and Civil Liberties Office. Unlessyou are otherwise 
advised, no PIA is required. (FBI and DOJ reviewing officials reserve the right to require a PIA.)) 

_NO (If "no," go to section III to determine if afull or short-form PIA is required.) 


III. Full or Short-Form PIA 


1. Is the system a major information system (as listed on OGC's FBINET website)? 
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FBI PRIVACY THRESHOLD ANALYSIS (PTA) 
NAME OF SYSTEM: DEPUTATION DATABASE 


_YES (If "yes," a full PIA is required. PTA is complete.) 

_NO (If "no," please continue to question 2.) 

2. Does the system involve routine information AND have limited use/access? 


_YES A short-form PIA is required. (l.e.,you need only answer Questions 1.1,1.2,2.1,3.1,4.1,5.1 (if appropriate), 6.2,6.3, 

and 8.9 of the PIA template.) Please note that FBI 
and DOJ reviewing officials reserve the right to 
require completion of a full PIA. (PTA is 
complete—forward with PIA.) 


_NO (If "no," a full PIA is required. PTA is complete.) 
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NAME OF SYSTEM: [ 


b3 

b7E 


FBI SYSTEM CONTACT PERSON 

FBI OGC/PCLU POC 

Name: 1 _|_ 

Name: AGCl i 

Program Office"! 1 

1 - 1 1 - 1 

r 1 

Phone: | j 

Division: Directorate of Intelligence 

Room Number: 7338 

Phone: | I 


Room Number: 11715 


Date PTA submitted for approval: 12/31/2007 



FBI DIVISION APPROVALS 



Program Division: Directorate of Intelligence]_j 

FBIHQ Division: Directorate of Intelligence! 1 


1 1 

1 1 

Program Manager 

Signature: 


(or other appropriate 

Date signed: 2/4/2008 


executive as Division 

Namej | 


determines) 

Title: Unit Chief 


Division Privacy Officer 

Signature: 

Signature: 


Date signed:1/16/2008 

Date signed: 1/16/2008 


Name:] [ 

Name:| j 


Title: Division Privacy Officer 

Title: Division Privacy Officer 


Upon Division approval,, forward signed hard copy plus electronic copy to OGC/PCLU (JEH Room 7338). 

FINAL FBI APPROVAL:_ 


FBI Privacy and Civil Liberties Officer 

Signature: 

Date Signed: 2/14/2008 

Name: David C. Larson 

Title: Acting Deputy General Counsel 




Upon final FBI approval, FBI OGC will distribute as follows: 

1 - Signed original to 190-HQ-C1321794 


1 - DOJ Privacy and Civil Liberties Office-Main Justice, Room 4259 

2 - FBI OCIO / OIPP 

1 - FBI SecD (electronic copy via e-mail) 

2* - Program Division POC /Privacy Officer 
2*- FBIHQDivision POC/Privacy Officer 

(*please reproduce as needed for Program/Division file(s)) 


1 - OGC\PCLU intranet website 
1 - PCLU Library 
1-PCLU Tickler 
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FBI PRIVACY THRES HOLD ANAL YSIS (PTA) 
NAME OF SYSTEM: | | b3 
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(OGC/PCLU (Re 


J7/06/07) 


For efficien cy, a system owner or program manager can be aided in making the determination of whether a Privacy Impact Assessment 
(PIA) is required by conducting and following Privacy Threshold Analysis (PTA). 

Whether or not a PIA is required, the system owner/program manager should consult with the FBI Records Management Division (RMD) to 
identify and resolve any records issues relating to information in the system. 

A PTA contains basic questions about the nature of the system in addition to a basic system description. The questions are as follows: 

A. General System Description: 


1. Type of information in the system: 



information will exist independently in the FBI's system of records. Its inclusion in the database is necessaiy in order for the FBI to 
accurately and efficiently address its Departmental reporting and retention requirements and address anticipated reporting needs. 


[ I datawill include: 

j j b3 

b7E 
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a. If the system is solely related to internal government operations please provide a brief explanation of the quantity and type of 
employee/contractor information: N/A 


2. Purpose for collecting the information and how it will be used: 



prompt retrieval of certain sorts of information. 
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FBI PRIVACY THRESH OLD ANAL YSIS (PTA) (OGC/PCLU (Rev. 07/06/07) 

NAME OF SYSTEM: | | b3 

b7E 

password restricted-access user interface enhances security and reduces the likelihood of operator error. Existing password protection 
will, in the future, permit systems administrators the ability to track and identify user activity. 


4. Means of accessing the system and transmitting information to and from the system: 


The ] [ database will be used by program managers in the Directorate of Intelligence to comply with Departmental record 

retention and reporting requirements. As it will initially be implemented, only a limited number of Directorate of Intelligence personnel 
will have | [ privileges. They will perform all data entiy, searching, and report production operations based upon information b3 

provided by field offices and other components. Once it is populated with real data, the system will be classified at the "Secret" level. k7I 

Access to the system will require physical access to a classified, FBINET-capable computer as well as authorized access to a shared folder 
located on a server to which some Directorate of Intelligence personnel are mapped. Although there will be few authorized users of this 
system ) | is also password protected. Usage of the system will be auditable (beyond presently possible network activity auditing) 

in thefuture, pending the completion of system enhancements. 


The information appearing in the | ~~| system will be,for the most part, administrative. The risk to the FBI and the harm to 
the national security which would result from the unauthorized disclosure of information such as | 1 

J Icould, cumulatively, be serious, but the Directorate of Intelligence believes that the 


protections i n place adequately ensure that that data will remain secure. 


All of the data which populates or otherwise appears inthe | [ database will exist separately and independently in the FBI's 

system of records. Decisions to index any of that data in the FBI's system of records will be made by field offices or other FBI components 
on the basis of established indexing policy. Indexing of records or other information inth d S ystem will be prohibited and no 

such indexing will occur. 


As th^ [develops momentum, it is likely that the Directorate of Intelligence will consider the b3 

distribution of limited access to the database (e.g. certain data entiy forms) to field offices via the FBI's secure Intranet. An amended b71 

Privacy Threshold Analysis or Privacy Impact Assessment will precede any such change. 


5. Who within FBI will have access to the information in the system and controls for ensuring that only authorized 
persons can access the information: 

Avery small number of users (program managers assigned to the Directorate of Intelligence ! I k3 

| | have administrative (including data entiy and modification) privileges. A larger group within the Directorate of ' J 

Intelligence will have "read only" and queiying capability. 


The Supplemental Guidelines require reporting from the FBI to the Department of Justice's National Security Division and/or the 
Deputy Attorney General. Certain reports are, thereafter, forwarded by the National Security Division to the Attorney General or the 
Deputy Attorney General. Some of the information in the database will be shared by the FBI's Directorate of Intelligence, its owner, with 
the Office of the General Counsel and other FBI components. 


6 . Who outside the FBI will have access to the information in the system and controls for ensuring that only authorized 
persons can access the information: 
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FBI PRIVACY THRESHOLD ANALYSIS (PTA) 
NAME OF SYSTEM: I 1 


b3 
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(OGC/PCLU (Rev. 07/06/07) 


No dissemination of the data in the database to any entity outside of the Department of Justice is planned at this time. □ 
|nay, in the future, request information about the database or the reports derived from it. 


7. Has this system been certified and accredited by the FBI Security Divisions? _Yes x No 

Certification and accreditation have not been sought for this small, classified, program-specific access database for reasons 
related to its limited purpose, small size, and restricted access. Disseminable reports generated by the database were previously 
reviewed by the Security Division. 


Know 


Is this system encompassed within an OMB-300? _Yes 

(if yes, please attach copy of latest one.) 


I. Was the system developed prior to April 17, 2003? 

_YES (If "yes," proceed to Question 1.) 

x NO (If "no," proceed to Section II.) 

1. Has the system undergone any significant changes since April 17,2003? 

_YES If "yes," please explain the nature of those changes: 

(Continue to Question 2.) 

_NO (If "no," the PTA is complete and should be sent to FBI OGC's Privacy and Civil Liberties Unit (PCLU) for review, approval, 

and forwarding to DOJ's Privacy and Civil Liberties Office. Unlessyou are otherwise advised, no PIA is required.) 

2. Do the changes involve the collection, maintenance, or dissemination of information in identifiable form about individuals? 

_YES (If "yes," please proceed to Question 3.) 

_NO (If "no," the PTA is complete and should be sent to FBI OGC's Privacy and Civil Liberties Unit (PCLU) for review, approval, 

and forwarding to DOJ's Privacy and Civil Liberties Office. Unlessyou are otherwise advised, no PIA is required.) 

3. Is the system solely related to internal government operations? 

_YES If "yes,” is this a Major Information System (as listed on OGC's FBINET website)?: 

_Yes. (If "yes," afull PIA is required.. PTA is complete.) 

_No. (If "no," the PTA is complete and should be sent to FBI OGC's Privacy and Civil Liberties Unit (PCLU) for 

review, approval, and forwarding to DOJ's Privacy and Civil Liberties Office. Unlessyou are otherwise advised, 
no PIA is required. (FBI and DOJ reviewing officials reserve the right to require a PIA.)) 
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FBI PRIVACY THRESHOLD ANALYSIS (PTA) 
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(OGC/PCLU (Rev. 07/06/07) 


NO (If "no," go to section III to determine if a full or short-form PIA is required.) 


II. For systems developed after April 17, 2003. 

1. What is the purpose of the system? (Answer in detail unless details already provided in A. 2 above): 

See Section A.2. 

(Continue to Question 2.) 

2. Does the system collect, maintain or disseminate information in identifiable form about individuals? 

_YES (If "yes," please proceed to Question 3.) 

x NO (If "no," the PTA is complete and should be sent to FBI OGC's Privacy and Civil Liberties Unit (PCLU) for review, 

approval, and forwarding to DOJ's Privacy and Civil Liberties Office. Unless you are otherwise advised, no PIA is required.) 


3. Is the system solely related to internal government operations? 

_YES If yes,” is this a Major Information System (as listed on OGC's FBINET website)?: 

_Yes. (If yes,” afull PIA is required.. PTA is complete.) 

_No. (If "no," the PTA is complete and should be sent to FBI OGC's Privacy and Civil Liberties 

Unit (PCLU) for review, approval, and forwarding to DOJ's Privacy and Civil Liberties Office. Unlessyou are 
otherwise advised, no PIA is required. (FBI and DOJ reviewing officials reserve the right to require a PIA.)) 

_NO (If "no," go to section III to determine if afull or short-form PIA is required.) 


III. Full or Short-Form PIA 

1. Is the system a major information system (as listed on OGC's FBINET website)? 

_YES (If "yes," afull PIA is required. PTA is complete.) 

_NO (If "no," please continue to question 2.) 

2. Does the system involve routine information AND have limited use/access? 

_YES A short-form PIA is required. (l.e.,you need only answer Questions 1.1,1.2,2.1,3.1,4.1,5.1 (if appropriate), 6.2, 

6.3, and 8.9 of the PIA template.) Please note that 
FBI and DOJ reviewing officials reserve the right to 
require completion of afull PIA. (PTA is 
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FBI PRIVACY THRESHOLD ANALYSIS (PTA) 
NAME OF SYSTEM: □ £ 


complete—forward with PIA. 


(If "no," a full PIA is required. PTA is complete.) 
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FBI Privacy Threshold Analysis (PTA) Cover Sheet 


NAME OF SYSTEM: FTTTF System[ 


b3 

b7E 


FBI SYSTEM CONTACT PERSON 

Name: 

Program Manager: 

Division: Counterterrorism Division 
Unit: Foreign Terrorist Tracking Task Force 
Phone: 

Date PTA submitted for approval: 8/16/2007 


FBI OGC/PCLU POC 


Name: 

Phone: _ 

Room Number: LX-1 3S-126 


b6 

b7C 


FBI DIVISION APPROVALS. A PIA (and/or PTA) should he prepared/approved by the 
cognizant program management in collaboration with IT, security, and end-user management and 
OGC/PCLU. (PIAs/PTAs relating to electronic forms/questionnaires implicating the Paperwork 
Reduction Act should also be coordinated with the RMD Forms Desk.) If the subject of a PTA/PIA is 
under the program cognizance of an FB1HQ Divi sion, prior to forwarding to OGC the PT A/PIA must, 
also be referred to the FBIHQ Division for program review and approval, if required by the FBIHQ 
Division. _ 



Program Division: 

FBIHQ Division: Counterterrorism 


[insert division name] 

Division 

Program Manager 

Signature: 

Signature: /s/ 

(or other appropriate 

Date signed: 

Date signed: 8/22/2007 

executive as Division 

Name: 

Name: Michael V. Caputo 

determines) 

Title: 

Title: Acting Section Chief, JTTTF 

Division Privacy 

Signature: 

Signature: 

Officer 

Date signed: 

Date signed: 


Name: 

Name: 


Title: 

Title: 


Upon Division approval, forward signed hard copy plus electronic copy to OGC/Privacy and Civil 
Liberties Law Unit (JEH Room 7338). 


FINAL FBI APPROVAL: 


FBI Privacy and Civil Liberties 

Signature :/s/ 


Officer 

Date Signed 

8/23/2007: 


Name: 

David C. Larson 


Title: 

Acting Deputy General Counsel 


Upon final FBI approval, FBI OGC will distribute as follows: 

1 - Signed original to 190-HQ-C1321794 
Copies to: 

1 - DOJ Privacy and Civil Liberties Office-Main Justice, Room 4259 1 - OGCYPCLU intranet website 

1 - FBI OCIO 1 - PCLU Library 

1 - FBI SecD (electronic copy via e-mail) 1 - PCLU Tickler 

2*- Program Division POC /Privacy Officer 
2*- FBIHQ Division POC /Privacy Officer 

(*please reproduce as needed for Program/Division file(s)) 
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FBI PRIVACY THRESHOLD ANALYSIS (VTA) _ 

NAME OF SYSTEM: FTTTF l I ^ 

For efficiency, a system owner or program manager can be aided in making the determination of whether a 
Privacy Impact Assessment (PIA) is required by conducting and following Privacy Threshold Analysis 
(PTA). 


Whether or not a PIA is required, the system owner/program manager should consult with the FBI Records 
Management Division (RMD) to identify and resolve any records issues relating to information in the 
system. 


A PTA contains basic questions about the nature of the system in addition to a basic system description. 
The questions are as follows: 


A. General System Description: Please briefly describe: 

__ (U/FOUO) | ZlFTTTF System. 

|___ I The FTTT F 

System is the subject of a PIA, 1 The FT1 TF System PIA includes ! I This 

PTA addresses specifically ! | 

(U/FOUO) 1. Type o f information in the system: | 

I | but do not contain information. 


b3 

b7E 


b3 

b7E 


a. If the system is solely related to internal government operations please provide a 
brief explanation of the quantity and type of employee/contractor information: n/a 

(U/FOUO) 2. Purpose for collecting the information and how it will be used: n/a 

(U/FOUO) 3, The system's structure (including components/subsystems):! I 

f | b7E 


(U/FOUO) 4. Means of accessing the system and transmitting information to and from the system: 

As stated in the FTTTF System PIA, “Access to the system is controlled under established security access 
controls to only cleared personnel, as certified and accredited (C&A) by the FBI.” 

(U/FOUO) 5. Who within FBI will have access to the information in the system and controls for 
ensuring that only authorized persons can access the information? See FTTTF System PIA. The system is 
managed and updated by assigned and cleared information technology specialists. 

(U/FOUO) 6. Who outside the FBI will have access to the information in the system and controls for 
ensuring that only authorized persons can access the information? See FTTTF System PIA and update. 


1 On October 17, 2005, the FBI's Privacy and Civil Liberties Officer (formerly the FBI Senior Privacy 
Official) approved a Privacy Impact Assessment (PIA) for the FTTTF System, also known as the FTTTF 
Datamart, subject to conditions. The 10/17/2005 PIA was subsequently updated, on 9/14/2006, to 
encompass additional data sets approved by the FBI Privacy and Civil Liberties Officer. 66F-HQ- 
C1321794 serial 213 and 66F-HQ-C1321794 serial 307. As noted in the FTTTF PIA dated 10/17/2005, 
the FTTTF system is a national security system and is therefore exempt from the PIA requirements of 
section 208 of the E-Govemment Act of2002, P.L. 107-347. 
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FBI PRIVACY THRESHOLD ANALYSIS IPTA1 
NAME OF SYSTEM: FTTTFj 


b3 

b7E 


Only authorized personnel, including contractors and other government agency task force members, have 
access to the information in the FTTTF system. These individuals are cleared, receive indoctrination and 
training and sign appropriate non-disclosure agreements and other access documentation prior to gaining 
access to the data. Access is regulated, maintained and documented by system administrators. The 
FTTTF has the ability to restrict user access and does restrict access in certain cases. 

(U/FOUO) 7. Has this system been certified and accredited by the FBI Security Division? _x_Yes 
_No ' 

(L’/FOUO) 8. Is this system encompassed within an OMB-300? _x_Yes _No _Don't Know 

(Please attach copy of the current one .) 

I. Was the system developed prior to April 17, 2003? 

x YES (If “yes,” proceed to Question 1.) 

_NO (If “no,” proceed to Section II.) 

1. Has the system undergone any significant changes since April 17, 2003? 

x YES If “yes,” please explain the nature of those changes: See FTTTF System PIA. 
(Continue to Question 2.) 

_NO (If “no,” the PTA is complete and should be sent to FBI OGC’s Administrative 

Law Unit for review, approval, and forwarding to DOJ’s Privacy and Civil 
Liberties Office. Unless you are otherwise advised, no PIA is required.) 

2. Do the changes involve the collection, maintenance, or dissemination of information in 
identifiable form about individuals? 

_YES (If “yes,” please proceed to Question 3.) 

_x_ NO (If “no,” the PTA is complete and should be sent to FBI OGC’s Administrative 

Law Unit for review, approval, and forwarding to DOJ’s Privacy and Civil 
Liberties Office. Unless you are otherwise advised, no PIA is required.) 

3. Is the system solely related to internal government operations? 

_YES If "yes," please provide a brief explanation of a) the purpose of the system, and b) 

quantity and type of employee/contractor information: 

_x_ NO (If the answer to Question 3 is “no” go to subsection III to determine if a full or 
short-form PIA is required.) 
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FBI PRIVACY THRESHOLD ANALYSIS £PTAj 
NAME OF SYSTEM: FTTTFl 


b3 

b7E 


II. For systems developed after April 17,2003. 

1. What is the purpose of the system? (Answer in detail and proceed to Question 2.) 

2. Does the system collect, maintain or disseminate information in identifiable form about 

individuals? 

_ YES (If “yes,” please proceed to Question 3.) 

NO (If “no,” the PTA is complete and should be sent to FBI OGC's Administrative Law 
Unit for review, approval, and forwarding to DOJ’s Privacy and Civil Liberties 
Office. Unless you are otherwise advised, no PIA is required.) 

3. Is the system solely related to internal government operations? 

_ YES If "yes," please provide a brief explanation of a) the purpose of the system, and b) 

quantity and type of employee/contractor information: 

_ NO (If “no,” go to section III to determine if a full or short-form PIA is required.) 

III. Full or Short-Form PIA 

1. Is the system a major information system (as listed on OGC’s FBINET website)? 

_ YES (If “yes,” a full PIA is required. PTA is complete.) 

x NO (If “no,” please continue to question 2.) 

2. Does the system involve routine information AND have limited use/access? 

_ YES If "yes, please explain what type of information is collected and the access 

provided: 

A short-form PIA is required. (I.e., you need only answer Questions 1.1, 1.2, 2.1, 

3.1, 4.1, 5.1 (if appropriate), 6.2, 6.3, and 8.9 of the PIA template.) Please note 
that FBI and DOJ reviewing officials reserve the right to require completion of a 
full PIA. (PTA is complete - forward with PIA.) 

If “no.” a full PIA is required PTA is complete .) I | b3 

HfiTTF S ystem, f | b7E 

~| The Fl IFF System is already the subject of a current 



This is a privileged FBI communication; do not circulate outside the FBI without the 
permission of the Office of the General Counsel. 
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FBI PRIVACY THRESHOLD ANALYSIS (PTA) 

(equivalent to the DOJ Initial Privacy Assessment (IPA)) 


(OGC/PCLU (Rev. 12/05/08) 


NAME OF SYSTEM/PROjECT: [ 


Derived frorss: 

SYSTEM/PROJECT POC 

FBI OGC/PCLU POC 


NameJ j 

Name: 

Reason: 

Program Office: Administrative Projects Unit (APU) 

Phone: 

Declassify On: 

Division: Office of IT Program Management (OIPM) 

Room Number: 


Phone] j 



Room Number: 1829 



FBI DIVISION INTERMEDIATE APPROVALS [complete as necessary] 



Program Manager (or other appropriate executive as 

Division determines) 

Division Privacy Officer 

Program Division: [Criminal 

Signature: 

Signature: 

Investigative Division] 

Date signed: 

Date signed: 


Namej ] 

Name: 


Title: CID Project Manager 

Title: 

FBIHQDivision: 

Signature: 

Signature: 

[Office of IT Program 

Date signed: 

Date signed: 

Management (OIPM)] 

Name:] j 

Name: 


Title: OIPM Program Manager 

Title: 


Additional division(s) approvals may be added as warranted: 


After all division approvals, forward signed hard copy pins electronic copy to FBI OGC/PCLU ({EH 7338). 

(The FBI Privacy and Civil Liberties Officer's determinations, conditions, and/or final approval will be recorded on the following page.) 


Upon final FBI approval, FBI OGC/PCldJ will distribute as follows: 

1 - Signed original to file 190-HQ.-CI 321794 (fwd to)EH 1B204 via PA-520) 

Copies (recipients please print/reproduce as needed for Program/Division file(s)): 

1 - DO| Office of Privacy and Civil Liberties (via e-mail to £nya0/;i®usdqj.gov) 

(if classified, via hand delivery to 1331 Penn. Ave. NW, Suite 940,20530) 

2 - FBI OCIO / OIPP (|EH 9376, attn | | 

1 - FBI SecD/AU (electronic copy: via e-mail to Lic j | b6 

1 - RMD/RMAU (attrt j | b7C 

2 - Program Division POC/Privacy Officer 
2 - FBIHQDivision POC /Privacy Officer 


1 -OGC\PCLU intranet 
1 - PCLU UC 
1 - PCLU Library 
1 - PCLU Tickler 


.SNCLASSSRED 
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INAL FBI APPROVAL / DETERMINATIONS / CONDITIONS: 


PIA required: _X_No _Yes: SORN/SORN revision required: _No _Yes: 

Applicable SORN(s): 

Notify FBI RMD/RIDS per MIOG 190.2.3: _No _Yes 

Prepare/revise/add Privacy Act (e)(3) statements for related forms? _No _Yes-forms affected: 

The program should consult with RMD to identify/resolve any Federal records/electronic records issues. 

Other: 


David C. Larson, Deputy General Counsel 
FBI Privacy and Civil Liberties Officer 


Signature: David C. Larson 
Date Signed: 1/22/09 
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FBI PTA: [ 

I. INFORMATION ABOUT THE SYSTEM / PROJECT 

1. Provide a general description of the system or project that includes: name of the system/project, including associated 
acronyms; structure of the system/project, purpose; nature of the information in the system and how it will be used; who will have 
access to the information in the system and the manner of transmission to al users. (This kind of information may be available in 
the System Security Plan, if available, or from a Concept of Operations document, and can be cut and pasted here.): 

In the conduct of investigations into financial institutions and related organizations, it is common that a large number of documents are 
acquired (through subpoenas and voluntary productions) in all criminal sub-programs from a number of different sources and in various 
formats. The documents are reviewed, annotated, categorized, and tracked. Throughout the duration of an FBI case, the FBI may 
exchange this data with partner agencies and lawfirms. This is a significant activity in large document-intensive cases such as corporate 
frauds. The FBI and the U.S. Securities and Exchange Commission (SEC) often conduct parallel investigations in major corporate fraud 
cases and partner with the U.S. Department of Justice (DOJ) to prosecute these cases. Therefore, the FBI needs to utilize 
Commercial-off-the-Shelf products that allow for the sharing of large amounts of data, the ability to easily search, and the ability to 
faci litate the use of the information during the discovery and trial phases of a case. 


b7E 

^ _ | s responsible for any PTA 

and/orPIA that their system requires. | [ will be Sensitive But Unclassified (SBU). The FBI may acquire 

additional typical case file information from various sources during the conduct of the investigation. That information will be logged and 
copies provided for input using the same process as described above with the appropriate level of security required. 

The results ofthe | [ Pilot will be factored into determining an appropriate IT solution to provide a long-term FBI Enterprise System for b7 

any major investigation. This Enterprise System Project will likely require a Privacy Threshold Analysis, and a Privacy Impact Assessment 
is expected to be completed. This project will go through thefull LifeCycle. 


2. Does the system/project collect, maintain, or disseminate any information about individuals in identifiable form, i.e., is information 
linked to or linkable to specific individuals (which is the definition of personally identifiable information (Pll))? 
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FBI PTA: 
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_X_NO. [if no, STOP. The PTA is now complete and after division approvals} should be submitted to FBI 

OGC/PCI.U for final FBI approval. Unless you are otherwise advised, no Pi A is required,] The project is designed to 

permit the FBI to use th j | i order to evaluate it for a long-term IT solution for enterprise case management purposes. 


YES. [Ifyes, please continue.] 


3. Does the system/project pertain only to government employees, contractors, or consultants? 
_NO. . —l YES. 


4. Is information about United States citizens or lawfully admitted permanent resident aliens retrieved from the system/project by 
name or other personal identifier? 

_NO. _YES. 

5. Are Social Security Numbers (SSNs) collected, maintained or disseminated from the system/project? 

_NO. _YES. If yes, check all that apply: 

_SSNs are necessary to establish/confirm the identity of subjects, victims, witnesses 

or sources in this law enforcement or intelligence activity. 

_SSNs are necessary to identify FBI personnel in this internal administrative system. 

_SSNs are important for other reasons. Describe: 

_The system/project provides special protection to SSNs (e.g.,SSNs are enciypted, hidden from all users via a a 

look-up table, or only available to certain users). Describe: 

_It is not feasible for the system/project to provide special protection to SSNs. Explain: 

6. Does the system/project collect any information directly from the person who is the subject of the information? 

_NO. [If no, proceed to question 7.] 

_YES. 

a. Does the system/project support criminal, CT, or FCI investigations or assessments? 

_YES. [Ifyes, proceed to question 7.] 

_NO. 
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FBI PTA: 


b7E 


b. Are subjects of information from whom the information is directly collected provided a written Privacy Act (e)(3) 

statement (either on the collection form or via a separate notice)? 

_NO. [The program will need to work with PCLU to develop/implement the necessary form(s).] 

_YES. Identify any forms, paper or electronic, used to requestsuch 

information from the information subject: 


7. Has the system undergone Certification & Accreditation (C&A) by the FBI Security Division (SecD)? 

_ NO. If no, indicate reason; if C&A is pending, provide anticipated completion date: This is a 

commercial-off-the-shelf (COTS) solution |~ | 

_YES. If yes, provide date of last C&A certification/re-certification: 

_Don't Know. 


8. Is this system/project the subject of an OMB-300 budget submission? 

_NO. _Don't know. _YES. Ifyes, please provide the date and name or 

title of the OMB submission: 

The Pilot system is not the subject of an OMB submission; however, the long-term solution will be the subject of an OMB submission as 
soon as the requirements have been identified and potential solutions investigated. 

9. Is this a national security system (as determined by the SecD)? 

_NO. _YES. _Don't know. 


11. Status of System/ Project: 

_ This is a new system/project in development. [If you checked this block, STOP. The P TA is now complete 

and after division approvals) should be submitted to FBI OGC./PCLU forfinal FBI approval and determination if 
PIA and/or other actions are required .] 

II. EXISTING SYSTEMS / PROJECTS 

1. When was the system/project developed? 

2. Has the system/project undergone any significant changes since April 17,2003? 

_ NO. [If no, proceed to next question (11.3).] 
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FBI PTA: 
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YES. lfyes,indicatewhichofthefollowingchangeswereinvolved (markall boxes that apply): 
_ A conversion from paper-based records to an electronic system. 


A change from information in a format that is anonymous or non-identifiable to a format that is identifiable to 
particular individuals. 

A new use of an IT system/project, including application of a new technology, that changes how information 
in identifiable form is managed. (For example, a change that would create a more open environment 
and/or avenue for exposure of data that previously did not exist.) 

A change that results in information in identifiable form being merged, centralized, or matched with other 
databases. 

A new method of authenticating the use of and access to information in identifiable form by members of the 
public. 

A systematic incorporation of databases of information in identifiable form purchased or obtained from 
commercial or public sources. 

A new interagency use or shared agency function that results in new uses or exchanges of information in 
identifiable form. 

A change that results in a new use or disclosure of information in identifiable form. 

A change that results in new items of information in identifiable form being added into the system/project. 

Changes do not involve a change in the type of records maintained, the individuals on whom records are 
maintained, or the use or dissemination of information from the system/project. 

Other. [Provide brief explanation]: 


3. Does a PIA for this system/project already exist? 


NO._YES. If yes: 


a. Provide date/title of the PIA: 


b. Has the system/project undergone any significant changes since the PIA? _NO. _YES. 

[The PTA is now complete a no after division approvals) should be submitted to FRi OGC/PCI.U for final FBI approval and determination if 
PIAansi/'or other actions are required.] 
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UNCLASSIFIED 


(OGC/PCLU (Rev. 05/15/09) 


FBI PRIVACY THRESH OLD ANALYSIS (PTA) 

(equivalent to the DOJ Initial Privacy Assessment (IPA)) 


NAME OF SYSTEM / PROJECT: Bureau Investigative Document Management System (BIDMAS) Phase II 


Derived Froror 

SYSTEM/PROJECT POC 

FBI OGC/PCLU PO 


Classified By; 

Namej j 

Name: AGcj 


Season; 

Program Office: BIDMAS 

PhoneJ 


Declassify On: 

Division: Office of IT Program Management (OIPM) 
Phone| [ 

Room Number: 3376 

Room Number: 7338 JEH 


FBI DIVISION INTERMEDIATE APPROVALS [complete as necessary consonant with Division polity'] 



Program Manager (or other appropriate executive as 

Division determines) 

Division Privacy Officer 

Program Division: [[Criminal 

Signature: 

Signature: 

investigative Division] j 

Date signed: approved 9/16/2009 

Date signed: 


Namej j 

Name: 


Title: CID Project Manager 

Title: 

FBIHQ. Division: 

Signature: 

Signature: 

[Office of IT Program 

Date signed: approved 10/5/09 

Date signed: 

Management (OIPM)j 

Namc| | 

Name: 


Title: OIPM Program Manager 

Title: 


After all division approvals, forward signed hard copy plus elec tronic copy to FBI OGC/PCLU (j£H 7338). 

(The FBI Privacy and Civil Liberties Officer's determinations, conditions, and/or final approval will be recorded on the following page.) 

Upon final FBI approval, FBI OGC/PCLU will distribute as follows; 


1 - Signed original to file 190-HQ.-C1321794 (fwd toJEH 1B204 via PA-520) 


Copies (recipients please print/reproduce a 


needed for Program/Division file(s)): 


1 - DOJ Office of Privacy and Civil Liberties (via e-mail 

(if classified, via hand deliveiy to 1331 Penn.Ave. NW, Suite 940,20530) 

2 - FBI OCIO/OIPP (JEH 9376,attn| [ 

1 - FBI SecD/AU (elec, copy: via e-mail to Utj 
1 - RMD/RMAU (attn£ 


Program Division POC/Privacy Officer 
FBIHQ_ Division POC /Privacy Officer 


1 -OGC\PCLU intranet 
1 -PCLU UC 
1 -PCLU Library 

1-PCLU Tickler b6 
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UNCLASSIFIED 


NAL FBI APPROVAL / DETERMINATIONS / CONDITIONS: 


_ PIA is required by the E-Government Act. 


_ PIA is to be completed as a matter of FBI/DOJ discretion. 


Is PIA to be published on FBI.GOV (after any RMD FOIA redactions)? 


_PIA is not required for the following reason(s): 

_System does not collect, maintain, or disseminate Pll. 

_System is grandfathered (in existence before 4/17/2003; no later changes posing significant privacy risks). 

_Information in the system relates to internal government operations. 

_System has been previously assessed under an evaluation similar to a PIA. 

_x_ No significant privacy issues (or privacy issues are unchanged). Privacy documentation provided by EOUSA r j | hould 

be sufficient to cover this activity, particularly as the records ultimately are passed to the U.S. Attorney's Offices where the cases are prosecuted. 

_Other (describe): 


Applicable SORN(s): Information that is 


:ained is uploaded to FBI case files and is therefore covered by the Central Records Systi 


Notify FBI RMD/RIDS per MIOG 190.2.3? _No _Yes-See sample EC on PCLU intranet website here: 

http:/7liort;e/DO/OGC/LTB/PCLU/PrivacyCivi|%20Liberties%20LiLirarv/fcrm for miool 90-2-3 ec.wpd 


SORN/SORN revision(s) required? 


se/add Privacy Act (e)(3) st 


RECORDS. The program should consult with RMD to identify/resolve any Federal records/electronic records issues. The system may contain Federal 
records whether or not it contains Privacy Act requests and, in any event, a records schedule approved by the National Archives and Records Administration 
is necessary. RMD can provide advice on this as well as on compliance with requirements for Electronic Recordkeeping Certification and any necessary 


David C. Larson, Deputy General Counsel 
FBI Privacy and Civil Liberties Officer 


Signature: David C. Larson 
Date Signed: 10/6/09 
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UNCLASSIFIED 


FBI PTA: Bureau Investigative Document Management System (BIDMAS) 

I. INFORMATION ABOUT THE SYSTEM / PROJECT 

1. Provide a general description of the system or project that includes: name of the system/project, including associated 
acronyms; structure of the system/project, purpose; nature of the information in the system and how it will be used; who will have 
access to the information in the system and the manner of transmission to al users. 

In the conduct of investigations into financial institutions and related organizations, it is common that a large number of documents are 
acquired for evidentiaiy and other purposes (through subpoenas and voluntary productions) in all criminal sub-programs from a number of 
different sources and in various formats. The documents are reviewed, annotated, categorized, and tracked. Throughout the duration 
of an FBI case, the FBI may exchange this data with partner agencies and law firms. This is a significant activity in large 
document-intensive cases such as corporate frauds. The FBI and the U.S. Securities and Exchange Commission (SEC) often conduct 
parallel investigations in major corporate fraud cases and partner with theU.S. Department of Justice (DOJ) to prosecute these cases. 

Therefore, the FBI needs to utilize a Commercial-off-the-Shelf (COTS) litigation information management tool that allows for the sharing of 
large amounts of data, the ability to easily search, and the ability to facilitate the use of the evidentiary information during the discovery 
and trial phases of a case. 

In order to more consistently and concisely assure that the evidentiary data required to be shared is available in an easily shared, consistent 
format, a pilot project was used to investigate the use of a COTS tool. |_| 

b7E 

| Because of the success of the pi I ot proj ect, 

Phase II is being implemented; the FBI is purchasing this COTS product for its own use as described below data. 

Phase II will provide Bureau-wide implementation of standardized processes and a tool set to support the immediate need of agents 
conducting major fraud investigations to organize evidentiaiy materials in anticipation of prosecution by an appropriate U.S. Attorney's 
office. | | 

b7E 

" ~| This product 

will be used to annotate, categorize, and track data. This information will then be analyzed and used as appropriate during the 
prosecution of a case. The information that is collected will be maintained throughout the investigatory portion of a case. Materials 
that will be used for prosecution will be forwarded to the U.S. Attorney's office for maintenance and contemporaneously uploaded into the 
appropriate FBI case file. Materials that are not used in connection with a prosecution will be purged. 


I | This will b7E 

allow the information to be limited only to designated users of the case. Within the case users, the case agent will determine the access 
of the other agents/analysts working the case. Their access can be restricted to a certain folder of data, or limited ability to annotate. 
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UNCLASSIFIED 


FBI PTA: Bureau Investigative Document Management System (BID.MA5) 

2. Does the system/project collect, maintain, or disseminate any information about individuals in identifiable form, i.e., is information 
linked to or linkable to specific individuals (which is the definition of personally identifiable information (Pll))? 

_NO. [if no, STOP. The PTA is now complete and after division approvai(s) should be submitted to F8S 

OGC/PCLU forfmal FBI approval. Unless you are otherwise advised, no PI A is required.] 

_X_YES. [Ifyes, please continue.] 


3. Does the system/project pertain only to government employees, contractors, or consultants? 
_X_NO. . .. YES. 


4. Is information about United States citizens or lawfully admitted permanent resident aliens retrieved from the system/project by 
name or other personal identifier? 

_NO. _X_YES. 


5. Are Social Security Numbers (SSNs) collected, maintained or disseminated from the system/project? 
_NO. _X_YES. If yes, check all that apply: 


_SSNs are necessary to establish/confirm the identity of subjects, victims, witnesses 

or sources in this law enforcement or intelligence activity. 

_SSNs are necessary to identify FBI personnel in this internal administrative system. 

_SSNs are important for other reasons. Describe: 

_The system/project provides special protection to SSNs (e.g.,SSNs are enciypted, hidden from all users via a 

look-up table, or only available to certain users). Describe: 

X It is not feasible for the system/project to provide special protection to SSNs. Explain: data obtained from 
banks or corporations may contain social security numbers 

6. Does the system/project collect any information directly from the person who is the subject of the information? 

X NO. [If no, proceed to question 7.] 

_YES. 

a. Does the system/project support criminal, CT, or FCI investigations or assessments? 

X YES. [Ifyes, proceed to question 7.] 

unoAsireo 
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UNCLASSIFIED 


FBI PTA: Bureau Investigative Document Management System (BIDMAS) 

_NO. 

b. Are subjects of information from whom the information is directly collected provided a written Privacy Act (e)(3) 

statement (either on the collection form or via a separate notice)? 

X NO. [The program will need to work with PCLU to develop/implement the necessary form(s).] 

_YES. Identify any forms, paper or electronic, used to requestsuch 

information from the information subject: 

7. Has the system undergone Certification & Accreditation (C&A) by the FBI Security Division (SecD)? 

_ NO. If no, indicate reason; if C&A is pending, provide anticipated completion date: 

X YES. If yes, provide date of last C&A certification/re-certification: Expecting ATT - for initial case 

production, on 9/30/03. We will continue::;; work towards ATO 

_Don't Know. 

8. Is this system/project the subject of an OMB-300 budget submission? Right now it is an OMB S3 

_NO. _Don’tknow. X YES. Ifyes, please provide the date and name 

or title of the OMB submission: BIDMAS 


9. Is this a national security system (as determined by the SecD)? 

_X_NO. _YES. _Don't know. 

10. Status of System/ Project: 

X This is a new system/project in development. [If you checked this block, STOP. The PTA is now asmplete 
and after division approval(s) should be submitted to FBI OGC/PCLU for final FBI approval and 
determination if PIA and/or other actions are required .] 
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UNCLASSIFIED 


FBI PTA: Bureau Investigative Document Management System (BIDMAS) 

II. EXISTING SYSTEMS / PROJECTS 

1. When was the system/project developed? 

2. Has the system/project undergone any significant changes since April 17,2003? 

_ NO. [If no, proceed to next question (11.3).] 

_ YES. lfyes,indicatewhichofthefollowingchangeswereinvolved (mark all boxes that apply): 

_ A conversion from paper-based records to an electronic system. 

_ A change from information in a format that is anonymous or non-identifiableto a format that is identifiable to 

particular individuals. 

_ A new use of an IT system/project, including application of a new technology, that changes how information 

in identifiable form is managed. (For example, a change that would create a more open environment 
and/or avenue for exposure of data that previously did not exist.) 

_ A change that results in information in identifiable form being merged, centralized, or matched with other 

databases. 

_ A new method of authenticating the use of and access to information in identifiable form by members of the 

public. 

_ A systematic incorporation of databases of information in identifiable form purchased or obtained from 

commercial or public sources. 

_ A new interagency use or shared agency function that results in new uses or exchanges of information in 

identifiable form. 

_ A change that results in a new use or disclosure of information in identifiable form. 

_ A change that results in new items of information in identifiable form being added into the system/project. 

_ Changes do not involve a change in the type of records maintained, the individuals on whom records are 

maintained, or the use or dissemination of information from the system/project. 

_ Other. [Provide brief explanation]: 

3. Does a PIA for this system/project already exist? _NO._YES. Ifyes: 

a. Provide date/title of the PIA: 


b. Has the system/project undergone any significant changes since the PIA? _NO. _YES. 

[The PTA is now complete and after division approval(s) should be submitted to FB! OGC/PCLU for final FBI approval and 
determination if PIA and/or other actions are required .] 
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FBI Privacy Threshold Analysis (PTA) Cover Sheet (ogc/pclu (Rev. 05/08/07) 


NAME OF SYSTEM: | | b7E 

FBI SYSTEM CONTACT PERSON 

Name: | | 

Program Office: OIPM 

Division: OCIO ^!L 

Phone l □ 

Room Number: 9330 

Date PTA submitted for approval: 6/08/07 

FBI DIVISION APPROVALS. A PIA (and/or PTA) should be prepared/approved by the cognizant program management in 
collaboration with IT, security, and end-user management and OGC/PCLU. (PiAs./PTAs relating to electronic forms/questionnaires implicating 
the Paperwork Reduction Act should also be coordinated with the RMD Forms Desk.) If the subject of a PTA/PiA is under the program 
cognizance of an FBIMQ_Division, prior to forwarding to OGC the PTA/PIA must also be referred to the FBIHC/DIvi.sion for program review and 
approval, if required by the FBiHQDivision. 



Program Division: Security Division 

FBIHQ_Division:[ins«?>t division name] 

Program Manager 

Signature:/s/ 

Signature: 

(or other appropriate 

Date signed: 6/11/07 

Date signed: 

executive as Division 

Name] | 

Name: 

determines) 

Title: IATU Unit Chief 

Title: 

Division Privacy Officer 

Signature:/s/ 

Signature: 


Date signed: 6/11/07 

Date signed: 


Name: Jeffery J. Berkin 

Name: 


Title: SecD AD (acting) /Privacy Officer 

Title: 


Upon Division approval, forward signed hard copy plus electronic copy to OGC/PCLU (JEH Room 7338). 


FINAL FBI APPROVAL: 


FBI Privacy and Civil Liberties Officer 

Signature:/s/ 



Date Signed: 7/13/07 



Name: 

David C. Larson 


Title: 

Acting Deputy General Counsel 


Upon final FBI 


approval, FBI OGC will distribute as follows: 

1 - Signed original to 190-HQ-C1321794 


1 - DOJ Privacy and Civil Liberties Office-Main Justice, Room 4259 
1 - FBI OCIO 

1 - FBI SecD (electronic copy via e-mail) 

2* - Program Division POC /Privacy Officer 
2*- FBIHQDivision POC/Privacy Officer 

(*please reproduce as needed for Program/Division file(s)) 


1 - OGC\PCLU intranet website 
1 - PCLU Libraiy 
1-PCLU Tickler 
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FBI PRIVACY THRESHOLD ANALYSIS (PTA) 
NAME OF SYSTEM: I 


b7E 


For efficien cy, a system owner or program manager can be aided in making the determination of whether a Privacy Impact Assessment 
(PIA) is required by conducting and following Privacy Threshold Analysis (PTA). 

A PTA contains basic questions about the nature of the system in addition to a basic system description. The questions are as follows: 

A. General System Description: Please briefly describe: 

1. Ty pe of information in the system: 

| | fhe only individual 

information recorded and stored is the userid (i.e. network logon id)l 

I -1 


a. If the system is solely related to internal government operations please provide a brief explanation of the quantity and type of 
employee/contractor information: 

The user id is extracted from the users workstation ! | The user enters their own user id. b7E 


Purpose for collecting the information and how it will be used: 



procedures, then ensure they ; 
general public. 


:y didn't follow proper security 
•e trained properly. The information collected is for internal use only and will not be made available to the 


3. The system's structure (including components/subsystems): 


b7E 


4. Means of accessing the system and transmitting information to and from the system: 

General users do not have access to the system. | 

|-— 1 - L | b7E 

^^^ "^his data contained in the system is not 
made available to the general public and is contained within the system itself. 

5. Who within FBI will have access to the information in the system and controls for ensuring that only authorized persons 
can access the information: 
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FBI PRIVACY THRESHOLD ANALYSIS (PTA) 
NAME OF SYSTEM: I 


b7E 


The system will be Certified and Accredited as a Tier 3 to ensure the proper security controls are in place. Privileged users (System admins) 
and the Enterprise Security Operations Center personnel will have access| | 


6. Who outside the FBI will have access to the information in the system and controls for ensuring that only authorized persons 
can access the information: 

No one outside has access to the system. All system data is contained within the Secret Enclave. 

7. Has this system been certified and accredited by the FBI Security Divisions? _Yes _XNo 

C&A activities are in process. 

8 Is this system encompassed within an OMB-300? _XYes _No _Don't Know 

(if yes, please attach copy of latest one.) 


I. Was the system developed prior to April 17, 2003? 

_YES (If "yes," proceed to Question 1.) 

_X_ NO (If "no," proceed to Section II.) 

1._Has the system undergone any significant changes since April 17,2003? 
_YES If "yes," please explain the nature of those changes: 


(Continue to Question 2.) 

_NO (If "no," the PTA is complete and should be sent to FBI OGC's Privacy and Civil Liberties Unit (PCLU) for review, approval, 

and forwarding to DOJ's Privacy and Civil Liberties Office. Unlessyou are otherwise advised, no PIA is required.) 

2. Do the changes involve the collection, maintenance, or dissemination of information in identifiable form about individuals? 

_YES (If "yes," please proceed to Question 3.) 

_NO (If "no," the PTA is complete and should be sent to FBI OGC's Privacy and Civil Liberties Unit (PCLU) for review, approval, 

and forwarding to DOJ's Privacy and Civil Liberties Office. Unlessyou are otherwise advised, no PIA is required.) 

3. Is the system solely related to internal government operations? 

_YES If "yes,” is this a Major Information System (as listed on OGC's FBINET website)?: 

_Yes. (If "yes," afull PIA is required.. PTA is complete.) 

_No. (If "no," the PTA is complete and should be sent to FBI OGC's Privacy and Civil Liberties Unit (PCLU) for 

review, approval, and forwarding to DOJ's Privacy and Civil Liberties Office. Unlessyou are otherwise advised, 
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FBI PRIVACY THRESHOLD ANALYSIS (PTA) 
NAME OF SYSTEM: | 


b7E 

no PIAis required. (FBI and DOJ reviewing officials reserve the right to require a PIA.)) 
NO (If "no," go to section III to determine if a full or short-form PIA is required.) 


II. For systems developed after April 17, 2003. 

1. What is the purpose of the system? (Answer in detail unless details already provided in A. 2 above): 

(Continue to Question 2.) 

2. Does the system collect, maintain or disseminate information in identifiable form about individuals? 

_X_YES (If "yes," please proceed to Question 3.) 

_NO (If "no,"the PTA is complete and should be sent to FBI OGC's Privacy and Civil Liberties Unit (PCLU) for review, approval, 

and forwarding to DOJ’s Privacy and Civil Liberties Office. Unlessyou are otherwise advised, no PIA is required.) 

3. Is the system solely related to internal government operations? 

_X_YES If yes,” is this a Major Information System (as listed on OGC's FBINET website)?: 

_Yes. (If "yes,” afull PIAis required.. PTA is complete.) 

_X_No. (If "no," the PTA is complete and should be sent to FBI OGC's Privacy and Civil Liberties Unit 

(PCLU) for review, approval, and forwarding to DOJ's Privacy and Civil Liberties Office. Unlessyou are 
otherwise advised, no PIAis required. (FBI and DOJ reviewing officials reserve the right to require a PIA.)) 

_NO (If "no," go to section III to determine if afull or short-form PIAis required.) 


III. 


Full 


or Short-Form PIA 

1. Is the system a major information system (as listed on OGC's FBINET website)? 

_YES (If "yes," afull PIAis required. PTA is complete.) 

_NO (If "no," please continue to question 2.) 

2. Does the system involve routine information AND have limited use/access? 

_YES A short-form PIAis required. (l.e.,you need only answer Questions 1.1,1.2,2.1,3.1,4.1,5.1 (if appropriate), 6.2,6.3, 

and 8.9 of the PIA template.) Please note that FBI 
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FBI PRIVACY THRESHOLD ANALYSIS (PTA) 
NAME OF SYSTEM: | 


and DOJ reviewing officials reserve the right to 
require completion of afull PIA. (PTA is 
complete—forward with PIA.) 


(If "no," a full PIA is required. 


PTA is complete.) 
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FBI Privacy Threshold Analysis (PTA) Cover Sheet (ogc/pclu (Rev. 07/06/07) 


NAME OF SYSTEM: National Stolen Art File 


FBI SYSTEM CONTACT PERSON 

FBI OGC/PCLU POC 

Name: I | 

Program Office: Art Theft Program/Major Theft Unit/Gang-Criminal 
Enterprise Section 

Division Criminal Investigative Division: 

Phone: 1 i 

Room Number: 3247 

Date PTA submitted for approval : July 26,2007 

Name: 

Phone: 

Room Number: 


FBI DIVISION APPROVALS. A PIA (and/or PTA) should be prepared/approved by the cognisant program management in 
collaboration with IT, security, and end-user management and OGC/PCLU. (PIAs/PTAs relating to electronic forms/questionnaires implicating 
the Paperwork Reduction Act should also be coordinated with the RMD Forms Desk.) It the subject of a PTA/PIA is under the program 
cognizance of an FBIHQ Division, prior to forwarding to OGC the PTA/PIA must also be referred to the FBIHQ. Division for program review and 
approval, if required by the FB!MQ.Division. 



Program Division: Art Theft Program 

FBIHQ.Division: Criminal investigative 

Program Manager 

Signature:/s/ 

Signature:/s/ 

(or other appropriate 

Date signed: Aug 2,2007 

Date signed: 7/26/07 

executive as Division 

Name: | j 

Name: Alex J. Turner 

determines) 

Title: Program Manager 

Title: Section Chief, Gang/Criminal Enterprise 

Section 

Division Privacy Officer 

Signature: 

Signature:/s/ 


Date signed: 

Date signed: 7/26/07 


Name] | 

Name:| j 


Title: Asst. Section Chief, OSS 

Title :Asst. Section Chief, OSS 


Upon Division approval, forward signed hard copy plus electronic copy to OGC/PCLU (|EH Room 7338). 


FINAL FBI APPROVAL: 


FBI Privacy and Civil Liberties Officer 

Signature:/s/ 



Date Signed: 8/3/07 



Name: 

David C. Larson 


Title: 

Acting Deputy General Counsel 


Upon final FBI approval, FBI OGC will distribute as follows: 


1 - Signed original to 190-HQ-C1321794 


1 - DOJ Privacy and Civil Liberties Office-Main Justice, Room 4259 

2 - FBI OCIO / OIPP 

1 - FBI SecD (electronic copy via e-mail) 

2* - Program Division POC /Privacy Officer 

2 *e[fi§Mj^Division POC/Privacy Officer E p |c _ 14 _ 06 _ 04 _ FB| _ FO|A _ 20150519 _ 6th _ production 


1 - OGC\PCLU intranet website 
1 - PCLU Library 
1-PCLU Tickler 
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(*please reproduce as needed for Program/Division file(s)) 
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FBI PRIVACY THRESHOLD ANALYSIS (PTA) 

NAME OF SYSTEM: National Stolen Art File 

For efficiency, a system owner or program manager can be aided in making the determination of whether a Privacy Impact Assessment 
(PIA) is required by conducting and following Privacy Threshold Analysis (PTA). 

Whether or not a PIA is required, the system owner/program manager should consult with the FBI Records Management Division (RMD) to 
identify and resolve any records issues relating to information in the system. 

A PTA contains basic questions about the nature of the system in addition to a basic system description. The questions are as follows: 

A. General System Description: Please briefly describe: 

1. Type of information in the system: 

The National Stolen Art File (NSAF) is a computerized index of stolen art and cultural property as 

reported to the FBI b y law enforcement agencies throughout the United States and internationally. _ 

Informati on includes) | b7E 

~1 The NSAF was established in 1979 and computerized in the 1990s. 

a. If the system is solely related to internal government operations please provide a brief explanation of the quantity and type of 
employee/contractor information: 

2. Purpose for collecting the information and how it will be used: 

The NSAF was developed to record stolen art and cultural artifacts which cannot be added to 
NCIC because they lack serial numbers. 

3. The system's structure (including components/subsystems): 


b7E 


4. Means of accessing the system and transmitting information to and from the system: 

The NSAF is only accessible on a single, stand-alone laptop kept in the Art Theft Program/Major Theft Unit office. 

Information is entered manually on the laptop and reports printed to a local (not networked) printer. 

5. Who within FBI will have access to the information in the system and controls for ensuring that only authorized persons 
can access the information: 

Only the Art Theft Program Manager enters and searches data in the NSAF. Results of searches can be requested by other FBI 
employees. 


6. Who outside the FBI will have access to the information in the system and controls for ensuring that only authorized persons 
can access the information: 

The Art Theft Program Manager will search the NSAF when art suspected to be stolen is located by the FBI or other law 
enforcement agencies. When stolen art is identified within the database as the result of a search, information ! I s supplied b7E 
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FBI PRIVACY THRESHOLD ANALYSIS (PTA) 
NAME OF SYSTEM: National Stolen Art File 


1 to the law enforcement agency requesting the search. 


Has this system been certified and accredited by the FBI Security Divisions? _Yes 

:ntly working on certifying and accrediting all of its laptops, including this one. 

jofall CID laptops. 


Is this system encompassed within an OMB-300? 

(If yes, please attach copy of latest one.) 


_Yes 


xNo 


Was the system developed prior to April 17, 2003? 

x YES (If "yes," proceed to Question 1.) 

NO (If "no," proceed to Section II.) 

1._Has the system undergone any significant changes since April 17,2003? 
_YES If "yes," please explain the nature of those changes: 


(Continue to Question 2.) 

x NO (If "no," the PTA is complete and should be sent to FBI OGC's Privacy and Civil Liberties Unit (PCLU) for review, approval, 

and forwarding to DOJ's Privacy and Civil Liberties Office. Unlessyou are otherwise advised, no PIA is required.) 

2. Do the changes involve the collection, maintenance, or dissemination of information in identifiable form about individuals? 

_YES (If "yes," please proceed to Question 3.) 

_NO (If "no," the PTA is complete and should be sent to FBI OGC's Privacy and Civil Liberties Unit (PCLU) for review, approval, 

and forwarding to DOJ's Privacy and Civil Liberties Office. Unlessyou are otherwise advised, no PIA is required.) 

3. Is the system solely related to internal government operations? 

_YES If "yes,” is this a Major Information System (as listed on OGC's FBINET website)?: 

_Yes. (If "yes," afull PIA is required.. PTA is complete.) 

_No. (If "no," the PTA is complete and should be sent to FBI OGC's Privacy and Civil Liberties Unit (PCLU) for 

review, approval, and forwarding to DOJ's Privacy and Civil Liberties Office. Unlessyou are otherwise advised, 
no PIA is required. (FBI and DOJ reviewing officials reserve the right to require a PIA.)) 

_NO (If "no," go to section III to determine if afull or short-form PIA is required.) 
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FBI PRIVACY THRESHOLD ANALYSIS (PTA) 
NAME OF SYSTEM: National Stolen Art File 


II. For systems developed after April 17, 2003. 

1. What is the purpose of the system? (Answer in detail unless details already provided in A. 2 above): 


(Continue to Question 2.) 

2. Does the system collect, maintain or disseminate information in identifiable form about individuals? 

_YES (If "yes," please proceed to Question 3.) 

_NO (If "no,"the PTA is complete and should be sent to FBI OGC's Privacy and Civil Liberties Unit (PCLU) for review, approval, 

and forwarding to DOJ’s Privacy and Civil Liberties Office. Unlessyou are otherwise advised, no PIA is required.) 


3. Is the system solely related to internal government operations? 

_YES If yes,” is this a Major Information System (as listed on OGC's FBINET website)?: 

_Yes. (If yes,” afull PIA is required.. PTA is complete.) 

_No. (If "no," the PTA is complete and should be sent to FBI OGC's Privacy and Civil Liberties Unit (PCLU) 

for review, approval, and forwardingto DOj's Privacy and Civil Liberties Office. Unlessyou are otherwise 
advised, no PIA is required. (FBI and DOJ reviewing officials reserve the right to require a PIA.)) 

_NO (If "no,"go to section III to determine if afull or short-form PIA is required.) 


III. Full or Short-Form PIA 


1. Is the system a major information system (as listed on OGC's FBINET website)? 
_YES (If "yes," afull PIA is required. PTA is complete.) 

_NO (If "no," please continue to question 2.) 

2. Does the system involve routine information AND have limited use/access? 


YES A short-form PIA is required. (l.e.,you need only answer Questions 1.1,1.2,2.1,3.1,4.1,5.1 (if appropriate), 6.2,6.3, 

and 8.9 of the PIA template.) Please note that FBI 
and DOJ reviewing officials reserve the right to 
require completion of afull PIA. (PTA is 
complete—forward with PIA.) 
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